Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 264

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
There's little chance of a hantavirus global outbreak. What the latest odds say
The Iran war will change global energy markets in these important ways, oil executives say
At 103 years old, I’m the ‘world’s oldest doctor’: My 3 rules for a long, happy life are so simple—I tell it to 'all my patients'
Can I eat this - homemade cheese edition
why don't my libby books show up in my kindle paperwhite library?
Passengers begin evacuating from cruise ship hit by hantavirus
Special Event: Rifftrax Shorts: ANIMALS
With Netflix new ad-free standard plan at $20, streaming's tipping point into old TV is getting closer
Bank of America says stocks like Apple have plenty of upside following earnings
Frontier jet hits and kills pedestrian on runway in Denver during takeoff